Uploaded image for project: 'CiviCRM'
  1. CiviCRM
  2. CRM-18458

"Forward an email" form should not impersonate the constituent

    Details

    • Type: Bug
    • Status: Open
    • Priority: Minor
    • Resolution: Unresolved
    • Affects Version/s: 4.7.6
    • Fix Version/s: Unscheduled
    • Component/s: CiviMail
    • Labels:
      None
    • Versioning Impact:
      Patch (backwards-compatible bug fixes)
    • Documentation Required?:
      None
    • Funding Source:
      Contributed Code

      Description

      Dropping the action.forward token in an email generates a link through which contacts may forward messages to their friends. This form sends mail with the FROM header sent to the constituent's email address. This is poor practice, is likely to be treated as spam, and depending on the SMTP provider may be rejected outright.

      Proposal is that the message come from the domain address and mention the sending user, e.g., "John Smith (john.smith458@example.org) has forwarded this message to you."

        Attachments

          Activity

            People

            • Assignee:
              pittstains Frank J. Gómez
              Reporter:
              pittstains Frank J. Gómez
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated:

                Time Tracking

                Estimated:
                Original Estimate - 2 hours
                2h
                Remaining:
                Remaining Estimate - 2 hours
                2h
                Logged:
                Time Spent - Not Specified
                Not Specified